APPSEC / SonarSource

SonarQube Advanced Security

SonarQube Advanced Security adds paid composition analysis and advanced static analysis to the quality platform. Dependency vulnerability and license-policy checks, SBOM import, and analysis modes have separate boundaries. The reviewed Enterprise-and-above requirement applies to the Advanced Security add-on on SonarQube Server, not to SonarQube Server itself.

Quality platform with paid software composition analysisResearch reviewed

What you are evaluating

The Advanced Security add-on requires an eligible Server edition and entitlement. Verify documented cloud-analysis and local-parsing data flows before enabling either mode; local parsing is not an air-gap guarantee. Compare its results with existing SCA coverage.

A useful evaluation context

A plausible evaluation context is an organization already using Sonar quality gates that is considering paid Advanced Security and must test data-flow and overlap with a dedicated SCA tool.

Documented capabilities

The vendor describes these capabilities in the linked sources. Availability depends on the product edition and supported environment.

  • Paid composition analysis with dependency vulnerability and license-policy checks.
  • SBOM import into the quality and security workflow.
  • Cloud analysis and local-parsing modes with different documented data flows, available as the Advanced Security add-on on SonarQube Server in Enterprise edition and above.

Where it fits in the work

  1. Confirm whether the Advanced Security add-on is entitled on this SonarQube Server (Enterprise edition or above per documentation) before expecting SCA results; do not treat Server itself as an Enterprise-only product.
  2. Analyze a lab project with dependencies and, after verifying the documented data flow and that the chosen mode is permitted, enable cloud analysis or local parsing.
  3. Import or produce SBOM evidence, compare findings with any existing SCA tool, and keep quality gates distinct from AppSec ownership.

APPLY THE IDEA / ILLUSTRATIVE EXERCISE

Make the outcome observable.

On a SonarQube Server install with the Advanced Security add-on entitled, analyze a lab project you own with a pinned vulnerable dependency and a license you intend to flag. Before enabling cloud analysis or local parsing, verify the documented data flow and that the chosen mode is permitted.

Evidence to look for

The dependency and license policy findings appear only where Advanced Security is entitled, the chosen data-flow mode is recorded as documented rather than as an air-gap guarantee, and an imported or generated SBOM lists the seeded component.

Use synthetic data and an authorized test environment. Agree the scope and recovery steps before enabling enforcement.

Questions for your evaluation

  1. Is the Advanced Security add-on entitled (Enterprise-and-above on SonarQube Server), or is the team looking at a Server or Community install without that add-on?
  2. Does the documented data flow for cloud analysis or local parsing leave the organization's residency boundary?
  3. How do Sonar dependency findings overlap with an existing SCA product, including license policy?

Names you may encounter: SonarQube Server · SonarQube SCA. Historical names do not establish current availability or feature equivalence.

Find your next idea.

Tip: press / to open search. Escape closes this window.